Skip to content

Update Gradle dependencies#11994

Open
dd-octo-sts[bot] wants to merge 1 commit into
masterfrom
ci/update-gradle-dependencies-20260719
Open

Update Gradle dependencies#11994
dd-octo-sts[bot] wants to merge 1 commit into
masterfrom
ci/update-gradle-dependencies-20260719

Conversation

@dd-octo-sts

@dd-octo-sts dd-octo-sts Bot commented Jul 19, 2026

Copy link
Copy Markdown
Contributor

What Does This Do

This PR updates the Gradle dependency locks for common and product modules.

Motivation

Refresh Gradle dependencies to make sure to apply the latest version available when bumping dependencies.

Contributor Checklist

  • Update PR title if a code change is needed to support one of those new dependencies

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@dd-octo-sts dd-octo-sts Bot added tag: no release notes Changes to exclude from release notes tag: dependencies Dependencies related changes labels Jul 19, 2026
@dd-octo-sts
dd-octo-sts Bot requested a review from a team as a code owner July 19, 2026 05:14
@dd-octo-sts dd-octo-sts Bot added the tag: dependencies Dependencies related changes label Jul 19, 2026
@dd-octo-sts
dd-octo-sts Bot requested review from a team as code owners July 19, 2026 05:14
@dd-octo-sts
dd-octo-sts Bot requested review from claponcet, dd-oleksii, jandro996, leoromanovsky and mhlidd and removed request for a team July 19, 2026 05:14

@datadog-official datadog-official Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Datadog Autotest: PASS

More details

Pure lockfile update with no source changes: io.sqreen:libsqreen bumped 17.3.0 → 17.4.0 across 18 core modules (AppSec WAF library), JaCoCo 0.8.14 → 0.8.15 in test-utils only, and minor scope corrections for annotation/transitive deps. The 430 instrumentation-test and smoke-test lockfiles left at 17.3.0 are intentional per the PR's stated "common and product modules" scope.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Datadog Autotest · Commit 0e63e32 · What is Autotest? · Any feedback? Reach out in #autotest

@datadog-official

This comment has been minimized.

@dd-octo-sts

dd-octo-sts Bot commented Jul 19, 2026

Copy link
Copy Markdown
Contributor Author

🟢 Java Benchmark SLOs — All performance SLOs passed

Suite Status
Startup 🟢 pass

SLO thresholds are defined here based on automatically generated metrics. A warning is raised when results are within 5% of the threshold.

PR vs. master results
Scenario Candidate master Δ (95% CI of mean)
startup:insecure-bank:iast:Agent 14.03 s 14.06 s [-1.1%; +0.7%] (no difference)
startup:insecure-bank:tracing:Agent 12.96 s 12.93 s [-0.4%; +0.9%] (no difference)
startup:petclinic:appsec:Agent 16.95 s 16.72 s [+0.4%; +2.4%] (maybe worse)
startup:petclinic:iast:Agent 16.97 s 16.91 s [-0.5%; +1.2%] (no difference)
startup:petclinic:profiling:Agent 16.71 s 16.35 s [-2.2%; +6.6%] (no difference)
startup:petclinic:sca:Agent 16.91 s 16.70 s [+0.3%; +2.2%] (maybe worse)
startup:petclinic:tracing:Agent 16.07 s 16.03 s [-0.8%; +1.3%] (no difference)

Commit: 0e63e32f · CI Pipeline · Benchmarking Platform UI


Load and DaCapo benchmarks can be triggered manually in the GitLab pipeline. Results will appear in the Benchmarking Platform UI after completion.

@PerfectSlayer PerfectSlayer left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking good. Retrying test_inst_latest

@PerfectSlayer

Copy link
Copy Markdown
Contributor

/merge

@gh-worker-devflow-routing-ef8351

gh-worker-devflow-routing-ef8351 Bot commented Jul 20, 2026

Copy link
Copy Markdown

View all feedbacks in Devflow UI.

2026-07-20 06:42:16 UTC ℹ️ Start processing command /merge


2026-07-20 06:42:27 UTC ℹ️ MergeQueue: waiting for PR to be ready

This pull request is not mergeable according to GitHub. Common reasons include pending required checks, missing approvals, or merge conflicts — but it could also be blocked by other repository rules or settings.
It will be added to the queue as soon as checks pass and/or get approvals. View in MergeQueue UI.
Note: if you pushed new commits since the last approval, you may need additional approval.
You can remove it from the waiting list with /remove command.


2026-07-20 06:59:08 UTC ℹ️ MergeQueue: merge request added to the queue

The expected merge time in master is approximately 2h (p90).


2026-07-20 07:12:28 UTCMergeQueue: The build pipeline contains failing jobs for this merge request

Build pipeline has failing jobs for 74549a2:

⚠️ Do NOT retry failed jobs directly (why?).

What to do next?

  • Investigate the failures and when ready, re-add your pull request to the queue!
  • If your PR checks are green, try to rebase/merge. It might be because the CI run is a bit old.
  • Any question, go check the FAQ.
Details

Since those jobs are not marked as being allowed to fail, the pipeline will most likely fail.
Therefore, and to allow other builds to be processed, this merge request has been rejected and the pipeline got canceled.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tag: dependencies Dependencies related changes tag: no release notes Changes to exclude from release notes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant